Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.29.1 Release.
🔗 CVE IDs covered (17)
📋 Description
CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-33245 — react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects
CVE-2026-42342 — react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint
CVE-2026-44249 — netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45149 — brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges
CVE-2026-48043 — netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
CVE-2026-50193 — jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb
CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
🎯 Affected products66
- Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:5daf10b66f5fbfb11269df3bce4857506e29ed397919aa24e7fb3f248a98e3cd_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:755170e3608b49fad1da1271cbd14ec08a54b35c004cc8f180c72c51c4e7db0b_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:a312402b6caf4841220b0f140ee64221c2616316617e8f1df71628e8855d7ee8_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:bca528a8f2f8ebedc209f05bfd7f9db41b2e76cb746b0ad73ce33b5b3f5d6c82_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:1e8da2750d8ccdd094c99a68c37ca500f29f28ba2e7c0eed3357e15f4cfdd183_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:462260f1d96b1227c08889d1aa79daf3118713702c73e704762214368e87531a_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:99d12fb419b26eb430eac178c2a2d434c9ba508db17c1c1c4093598bfeef566b_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:e95a69d2df193cb7a61607e42ceeec57fd122e8e28a28c776d9879173295d159_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:0e45311a6f90e08b6045f4baff18ad11e528bb6c8b4fd8e659b11b00d541349e_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:3fe4ee11f2344cfb7cf7343dcca9aaae7f9faebff2d6db70aa999d8aff82dff8_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:94763efe553381fa5d9abeced6ed0f3cffb0427a326e117b2cd19859914eef42_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:97112bad6bf3d8844ca0bda79b7d0839d16fa7efa7b58abd59d7a6f44912399c_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:35e473eed97efe209e4b0f064e9b4d7441b0391f3d66634b1267d1f942a53bae_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:4da408d8b9dd1368285e5f289dd89ab2f86f069e50d88b1241e997b88edbf7ed_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:6af7182edffac5d714a9943782e319ab0cc303799df7aaf1593f5eefed9fe3b9_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:aa822e3f4d4456b6b32607b38f2c121188cd6f3d63b13d876f5b0c206eb2478b_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:72602fbcafed639a0d65e84127aa184d0934ac1e565c1b9b75380c4a4a6b8987_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:4209dd2be299648561f82fc7e1913d62c6b2c8b61d0ce6d1beedc70a1f31f06b_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:ad1ffabc6bf85297081780cfecdfdc1d03870c4f778442e4a1896118d9b9a44c_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d0f49266156c7e0e772e98567c4f4bf60a5ad2bb69bf5aebdaeb2a69156f5eab_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:f5509bd819fd25fb635f214aba369e2c33c5a29cc3922c117104808556d783b2_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:0c1d83449f3015ed59f48b99e82562a797e1ef461e148ee540cfe8e11be2159f_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7347f1f8fbbdc9b8763bf4d9b0d3554901754cd26428acd8f1c0dac7d875205c_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:bd01751fd139ba6c68e3fb0fb4781322dbb829235c4334608f19693d07b1d95d_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:d117b4142feac814835c85b01084dbcbc85c85c9d17b9fa64d185c917bda5ade_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:00bc760d028882cd8dd442c1b3f129a54e193beb25556759443d59ed75ca5060_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:09abdc10e4c96f5c5794df2c337a5d5e766df45812d88fffd85cd477fde32397_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:928ead79d7e5258e67a5af980dd321d7095540ff39a965e978b93fd9c1803e83_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:cccf05e2bf90e0983a92af2944bed525dbc2501ac8920614a158474e9e921fa3_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- +36 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this Cross-Site Scripting (XSS) vulnerability, ensure that applications utilizing React Router's unstable React Server Components (RSC) APIs only process redirects from trusted sources. Avoiding the use of these unstable APIs in production environments where untrusted redirect sources cannot be guaranteed is also recommended. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Upgrade to a patched version to fully mitigate the issues (ref: https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:48124
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.29/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-12151
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-33245
- externalhttps://access.redhat.com/security/cve/CVE-2026-42342
- externalhttps://access.redhat.com/security/cve/CVE-2026-44249
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45149
- externalhttps://access.redhat.com/security/cve/CVE-2026-48043
- externalhttps://access.redhat.com/security/cve/CVE-2026-50193
- externalhttps://access.redhat.com/security/cve/CVE-2026-54512
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/cve/CVE-2026-6734
- externalhttps://access.redhat.com/security/cve/CVE-2026-9697
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48124.json